Integer wraparound in IVFFlat index build in pgvector before 0.8.6 allows a database user to write data out-of-bounds, which could lead to arbitrary code execution. Only 32-bit systems are affected.
References
| Link | Resource |
|---|---|
| https://github.com/pgvector/pgvector/commit/636a92a3395d2e036ffd40d07aeb400a708ae104 | Patch |
| https://github.com/pgvector/pgvector/issues/1006 | Issue Tracking Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-07-29 20:17
Updated : 2026-08-20 13:15
NVD link : CVE-2026-18022
Mitre link : CVE-2026-18022
CVE.ORG link : CVE-2026-18022
JSON object : View
Products Affected
pgvector_project
- pgvector
